The annual scramble
The board attests every year. The evidence is still assembled by hand.
s.30AC of the SOCI Act requires responsible entities of the asset classes prescribed by the CIRMP Rules to adopt and maintain a written CIRMP. Thirteen of the twenty-two asset classes carry it. The four hazard domains come from ss.8 to 11 of the Rules. The responsible entity gives the annual report to its regulator within 90 days after the end of the financial year, and the board approves it first. Today that pack is scrambled together. Spreadsheets, SharePoint folders, vendor exports, a consultancy retainer. Where OT meets IT GRC is where audit defensibility goes to die. The Enhanced CIRMP Rules 2026 commenced on 10 June 2026. They reach nine of the thirteen classes. Grace periods hold every one of the new requirements back to 10 June 2027 or 10 June 2028.
13%
of the cyber security incidents ASD responded to in FY2024-25 involved critical infrastructure, out of more than 1,200. Up from 11 per cent in FY2023-24.
ASD Annual Cyber Threat Report 2024-25
22%
of Commonwealth entities reached Essential Eight Maturity Level 2 in 2025. Up from 15 per cent in 2024.
The Commonwealth Cyber Security Posture in 2025
How it works
Three steps. Same engine every quarter.
The pack is no longer a project. It is a continuously assembled artefact your CISO signs off and the board attests to.
How cirmp AI turns the tool exports you already produce into a board-signed CIRMP pack.
Bring in
The exports your security and IT tools already produce. Dragos, Claroty, Microsoft Sentinel, CrowdStrike Falcon, ServiceNow IRM, Workday. No agents to install.
Ingest · existing telemetry
Assemble
The engine is being built to draft the four-hazard report. Every line cites its source artefact. Reasoning trail viewable offline by the regulator. The new Enhanced Rules 2026 controls are evidenced inside the same four categories.
Continuous · four hazards
Sign
Your CISO reviews and signs. Board signs the s.30AG attestation. SHA-256 sealed. Cited offline-verifiable.
Attest · s.30AG
What you walk away with
What's in the pack.
One signed PDF. Four hazards. A reasoning trail your regulator can verify offline.
Four hazard domains. Cyber and information security. Personnel. Supply chain. Physical and natural.
Built to reflect the Enhanced CIRMP Rules 2026. The same four categories, with the new credential, access and network-segregation controls evidenced inside them.
Reasoning trail · 4 citations
AESCSF framework mapping
IDM 02:14
Entra ID. MFA policy
IDM 02:21
Entra ID. Privileged users
IDM 02:21
CrowdStrike Falcon. March cycle
IDM 02:28
Signed PDF
One pack the board attests to. SHA-256 sealed, time-stamped, offline-verifiable.
Four hazards
Cyber. Personnel. Supply chain. Physical and natural. Covered by default.
Reasoning trail
Every claim cites the control it answers and the rationale it was assessed on.
Sovereign
Being built to be AU-hosted and AU-owned.
Why you can trust the pack
Built to be checked, not taken on faith.
A compliance pack is only worth as much as your ability to defend it. We build the pack so a reviewer can trace every line back to where it came from.
Every claim carries a reasoning trail
Each control statement links back to the control it answers and the rationale it was assessed on. You can follow the working, not just read the conclusion.
People own the legal wording
The statutory attestation and penalty wording is fixed by people, not generated by the model. The board approves the pack and the entity signs it.
Assurance-ready by design
The pack is built so an independent reviewer can verify our working line by line. SHA-256 sealed and offline-verifiable, so the check does not depend on us.
§ 30AC / § 30AG obligations
Failing to give the board-approved s.30AG annual report is a civil penalty of 150 penalty units. Maintaining the CIRMP itself (s.30AC) carries 200. A false or misleading report is a separate criminal offence. The board signs it. The entity is liable.
SOCI Act 2018. s.30AG, civil penalty provisions.
s.30AG is the annual board-approved reporting requirement under the SOCI Act 2018, a 150 penalty unit civil penalty if it is not met. s.30AC is the obligation to maintain a written CIRMP, 200 penalty units. Knowingly giving false or misleading information is dealt with under the Criminal Code, not as a SOCI civil penalty.
The selection rule
Different entities need different frameworks. cirmp AI is being built to pick the right one.
CIRMP is the report. It does not tell you which cyber framework to use as the spine. The Rules name five accepted frameworks at s.8(4). The entity chooses one and meets its condition. We suggest a starting point by environment, then evidence against whichever one you choose.
Footnote ·CIRMP Rules (LIN 23/006), section 8(4) names five cyber security frameworks with the condition each one carries: AS ISO/IEC 27001:2015 with no condition, the Australian Signals Directorate (ASD) Essential Eight Maturity Model at Maturity Level 1, the Framework for Improving Critical Infrastructure Cybersecurity with no condition, the Cybersecurity Capability Maturity Model (C2M2) at Maturity Indicator Level 1, and the 2020-21 Australian Energy Sector Cyber Security Framework (AESCSF) Core at Security Profile 1. The entity chooses one and meets its condition. Since 10 June 2026 the Rules also carry a separate table at s.8A(3) for the nine enhanced asset classes: AS ISO/IEC 27001:2023, the Essential Eight at Maturity Level 2, NIST CSF 2.0, C2M2 version 2.1 at Maturity Indicator Level 2, and the 2023 AESCSF Framework Core at Security Profile 2. An entity in the nine satisfies both tables under s.4A(3), and s.8A(3) sits inside a grace period to 10 June 2028. Section 8A(4) permits an equivalent framework in place of items 2, 4 or 5.
Pricing
Continuous engagement.
Not a one-off audit.
Two parts. Implementation up front. Then four cycles a year, engine always on.
Talk to us about pricing →One-off · Implementation
Get cirmp AI live in your environment.
Secure-cloud deployment in your tenancy. Connector mapping for your existing OT and IT tooling. Asset-class customisation.
Ongoing · Quarterly
Four cycles a year. Engine always on.
Four CIRMP cycles a year, fully assembled and signed. Engine runs continuously between cycles.
The next cycle
Twenty minutes.
See it assemble itself.
See a sample CIRMP pack assembled live from real-world exports.